UiChemy — Figma Converter for Elementor, Gutenberg and Bricks Security & Risk Analysis

wordpress.org/plugins/uichemy

Convert Figma Designs Templates into 100% Editable WordPress Websites. It's having figma to Elementor, Figma to Gutenberg & Figma to Bricks P …

8K active installs v4.7.0 PHP 7.4+ WP 6.6+ Updated Mar 6, 2026
figma-to-bricksfigma-to-codefigma-to-elementorfigma-to-gutenbergfigma-to-wordpress
98
A · Safe
CVEs total2
Unpatched0
Last CVEJan 12, 2026
Safety Verdict

Is UiChemy — Figma Converter for Elementor, Gutenberg and Bricks Safe to Use in 2026?

Generally Safe

Score 98/100

UiChemy — Figma Converter for Elementor, Gutenberg and Bricks has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Jan 12, 2026Updated 28d ago
Risk Assessment

The uichemy plugin v4.7.0 exhibits a generally good security posture due to its adherence to several security best practices, including the consistent use of prepared statements for SQL queries and a high percentage of properly escaped output. The presence of nonce and capability checks on all identified AJAX entry points is also a positive indicator. However, the static analysis reveals a significant concern with the presence of the `unserialize` function, which, if used with user-supplied input, can lead to critical remote code execution vulnerabilities. While the taint analysis did not flag critical or high severity issues, the two identified unsanitized path flows warrant attention as they could potentially be exploited in conjunction with other weaknesses. The vulnerability history, though showing no currently unpatched CVEs, indicates a past pattern of medium severity vulnerabilities including Cross-site Scripting and Missing Authorization, suggesting a need for continued vigilance and thorough auditing.

In conclusion, while uichemy v4.7.0 demonstrates strengths in fundamental security areas like output escaping and database query sanitization, the critical risk posed by the `unserialize` function and the potential for unsanitized path flows, coupled with its historical vulnerability profile, necessitates a cautious approach. The absence of unpatched CVEs is encouraging, but the underlying code signals and past incidents suggest that further review and potentially remediation of the `unserialize` usage are crucial for a robust security posture.

Key Concerns

  • Dangerous function 'unserialize' detected
  • Taint analysis found unsanitized paths
  • History of medium severity vulnerabilities
Vulnerabilities
2

UiChemy — Figma Converter for Elementor, Gutenberg and Bricks Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-69362medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

UiChemy <= 4.4.2 - Authenticated (Author+) Stored Cross-Site Scripting

Jan 12, 2026 Patched in 4.4.3 (8d)
CVE-2025-62013medium · 4.3Missing Authorization

UiChemy <= 4.0.0 - Missing Authorization

Oct 16, 2025 Patched in 4.0.1 (8d)
Code Analysis
Analyzed Mar 16, 2026

UiChemy — Figma Converter for Elementor, Gutenberg and Bricks Code Analysis

Dangerous Functions
6
Raw SQL Queries
0
4 prepared
Unescaped Output
1
102 escaped
Nonce Checks
10
Capability Checks
15
File Operations
1
External Requests
6
Bundled Libraries
0

Dangerous Functions Found

unserialize$elementor_plugin = unserialize(wp_remote_retrieve_body($response));includes\admin\class-uich-api.php:1655
unserialize$tpgb_plugin = unserialize(wp_remote_retrieve_body($response));includes\admin\class-uich-api.php:1843
unserialize$plugin_info = unserialize( wp_remote_retrieve_body( $response ) );includes\admin\class-uich-enqueue.php:352
unserialize$old_value = unserialize(serialize($global_classes));;includes\admin\globals\class-uich-atomic-globals.php:99
unserialize$old_value = unserialize(serialize($global_classes));includes\admin\globals\class-uich-atomic-globals.php:348
unserialize$old_value = unserialize(serialize($global_classes));includes\admin\globals\class-uich-atomic-globals.php:371

SQL Query Safety

100% prepared4 total queries

Output Escaping

99% escaped103 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
uich_api_call (includes\admin\class-uich-api.php:1589)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

UiChemy — Figma Converter for Elementor, Gutenberg and Bricks Attack Surface

Entry Points10
Unprotected0

AJAX Handlers 10

authwp_ajax_uich_regenerate_tokenincludes\admin\class-uich-api.php:79
authwp_ajax_uich_select_userincludes\admin\class-uich-api.php:80
authwp_ajax_uich_uichemyincludes\admin\class-uich-api.php:81
authwp_ajax_elementor_import_mediaincludes\admin\class-uich-atomic-imgs.php:7
authwp_ajax_uich_bricks_import_mediaincludes\admin\class-uich-bricks-imgs.php:3
authwp_ajax_uichemy_import_imagesincludes\admin\class-uich-copy-images.php:42
authwp_ajax_uich_install_wdesignincludes\admin\class-uich-enqueue.php:48
authwp_ajax_uich_boarding_storeincludes\admin\class-uich-enqueue.php:50
authwp_ajax_uich_activate_elementor_pro_pluginincludes\admin\class-uich-enqueue.php:66
authwp_ajax_uich_update_notice_countincludes\admin\class-uich-enqueue.php:68
WordPress Hooks 25
filterrest_pre_serve_requestincludes\admin\class-uich-api.php:75
filterupload_mimesincludes\admin\class-uich-api.php:76
filterhttp_request_timeoutincludes\admin\class-uich-api.php:77
filteruich_recommended_settingsincludes\admin\class-uich-api.php:83
actionrest_api_initincludes\admin\class-uich-api.php:85
actionelementor/initincludes\admin\class-uich-elementor.php:40
actionelementor/element/common/_section_responsive/after_section_endincludes\admin\class-uich-elementor.php:51
actionelementor/element/section/_section_responsive/after_section_endincludes\admin\class-uich-elementor.php:52
actionelementor/element/column/_section_responsive/after_section_endincludes\admin\class-uich-elementor.php:53
actionelementor/element/container/_section_responsive/after_section_endincludes\admin\class-uich-elementor.php:54
actionelementor/element/parse_cssincludes\admin\class-uich-elementor.php:56
actionelementor/editor/after_enqueue_scriptsincludes\admin\class-uich-elementor.php:58
actionadmin_menuincludes\admin\class-uich-enqueue.php:38
actionadmin_enqueue_scriptsincludes\admin\class-uich-enqueue.php:39
actionwp_enqueue_scriptsincludes\admin\class-uich-enqueue.php:40
actionenqueue_block_editor_assetsincludes\admin\class-uich-enqueue.php:43
actionadmin_enqueue_scriptsincludes\admin\class-uich-enqueue.php:46
actionadmin_headincludes\admin\class-uich-enqueue.php:52
actionelementor/editor/after_enqueue_scriptsincludes\admin\class-uich-enqueue.php:70
actionwp_loadedincludes\admin\class-uich-enqueue.php:75
actionwp_headincludes\admin\class-uich-enqueue.php:76
filteruich_manage_tokenincludes\admin\class-uich-token-manager.php:35
filteruich_manage_usermanagerincludes\admin\class-uich-usermanager.php:34
actionplugins_loadedincludes\class-uich-uichemy.php:63
filterplugin_row_metaincludes\notices\class-uich-plugin-page.php:68
Maintenance & Trust

UiChemy — Figma Converter for Elementor, Gutenberg and Bricks Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 6, 2026
PHP min version7.4
Downloads120K

Community Trust

Rating100/100
Number of ratings12
Active installs8K
Developer Profile

UiChemy — Figma Converter for Elementor, Gutenberg and Bricks Developer Profile

POSIMYTH

8 plugins · 460K total installs

85
trust score
Avg Security Score
96/100
Avg Patch Time
72 days
View full developer profile
Detection Fingerprints

How We Detect UiChemy — Figma Converter for Elementor, Gutenberg and Bricks

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/uichemy/assets/css/uichemy.css/wp-content/plugins/uichemy/assets/js/uichemy-frontend.js/wp-content/plugins/uichemy/assets/js/uichemy-backend.js/wp-content/plugins/uichemy/assets/js/uich-elementor-editor.js
Script Paths
/wp-content/plugins/uichemy/assets/js/uichemy-frontend.js/wp-content/plugins/uichemy/assets/js/uichemy-backend.js/wp-content/plugins/uichemy/assets/js/uich-elementor-editor.js
Version Parameters
uichemy/assets/css/uichemy.css?ver=uichemy/assets/js/uichemy-frontend.js?ver=uichemy/assets/js/uichemy-backend.js?ver=uich-addons-editor-js?ver=

HTML / DOM Fingerprints

CSS Classes
uich-containeruich-item
HTML Comments
UiChemy : Custom CSS
Data Attributes
data-uich-iddata-uich-type
JS Globals
window.uich_frontend_settings
REST Endpoints
/wp-json/uich/v2/uich_store_user_data
FAQ

Frequently Asked Questions about UiChemy — Figma Converter for Elementor, Gutenberg and Bricks